Multi-tenant SaaS Access Control via Segmentation and Virtualization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The Software as a Service (SaaS) architecture faces challenges in providing customization and ensuring security and privacy for customers, as it treats software applications as commodities available to all, lacking flexibility to meet diverse customer needs and potentially compromising security with centralized management across wide customer bases.
Innovation Solution
A system that manages user access to application-specific capabilities by correlating user identifiers with user roles and application-specific capabilities, using a security module to enforce access controls, allowing for customization and enhanced security through selective addition of security and privacy services, creating a virtual private Internet environment for multi-tenant service delivery.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If centralized management of SaaS applications is used, then scalability and maintenance are improved, but security concerns and customization limitations worsen
Solution Approach 1:
The patent segments the centralized SaaS platform into multiple isolated tenant environments, where each tenant's data and applications are logically separated. This segmentation allows centralized management benefits while preventing security risks from propagating across the entire system, as each tenant operates in an isolated namespace with controlled access to resources.
Solution Approach 2:
The patent introduces a virtualization layer as an intermediary between the centralized infrastructure and individual tenants. This virtualization intermediary manages resource allocation, enforces security policies, and provides customization capabilities while maintaining the underlying centralized architecture, thus resolving the conflict between centralized management and security concerns.
2Productivity
If centralized management of SaaS applications is used, then scalability and maintenance are improved, but customization capabilities worsen
Solution Approach 1:
The patent implements dynamic configuration capabilities within the virtualized tenant environments, allowing customization of application settings, data models, and user permissions without affecting the core centralized platform. This dynamic approach enables each tenant to adapt the software to their specific needs while maintaining the scalability benefits of centralized management.
Solution Approach 2:
The patent applies local quality by allowing each tenant to have customized configurations, data schemas, and application parameters within their isolated environment, while the overall platform maintains uniform centralized management. This enables customization at the local tenant level without compromising the global scalability and maintenance advantages of the centralized architecture.
3Adaptability or versatility
If separate application instances are generated for each customer (ASP model), then customization is improved, but maintenance difficulty and scaling complexity worsen
Solution Approach 1:
The patent merges multiple separate application instances into a single unified SaaS platform that serves multiple tenants simultaneously. By combining the instances while maintaining logical isolation through virtualization, the system achieves the customization benefits of separate instances without the maintenance complexity and scaling issues of managing multiple independent applications.
Data Source
AI summary
Managing user access to application-specific capabilities of a system includes maintaining data correlating application-specific capabilities for each of the applications of the system, where the application-specific capabilities of different applications are independent of each other. Managing user access also includes maintaining data correlating user identifiers with user roles, maintaining data correlating user roles with application-specific capabilities, and managing the data using a security module that accesses the data correlating application-specific capabilities, data correlating user identifiers, and the data correlating user roles. The system may have a plurality of tenants and wherein each of the tenants subscribes to one or more of the applications. Each of the users may correspond to a particular one of the tenants. Each tenant may subscribe to a particular set of applications/features.


